Image reports › ocimend.io/eclipse-temurin
ocimend.io/eclipse-temurin — vulnerabilities, FIPS 140-3 and fixes
ocimend.io/eclipse-temurin · Ubuntu 26.04.1 LTS
Latest: ocimend.io/eclipse-temurin:17.0.20.1_1-jdk-fixed · checked 2026-10-01
Not FIPS-ready
No. eclipse-temurin:17.0.20.1_1-jdk-fixed relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade C: 354 known vulnerabilities
354 known vulnerabilities in 40 packages (81 high); none has a fix available yet.
Open the full report → Get a fixed image Get a FIPS image Scan your own image
Critical, high and exploited vulnerabilities in 17.0.20.1_1-jdk-fixed
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| high | UBUNTU-CVE-2026-85091 | zlib1g 1:1.3.dfsg+really1.3.1-1ubuntu3.1 | no fix yet | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an |
| high | UBUNTU-CVE-2026-86145 | libpcre2-8-0 10.46-1build1 | no fix yet | PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regul |
| high | UBUNTU-CVE-2026-103111 | libpcre2-8-0 10.46-1build1 | no fix yet | PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data. |
| high | UBUNTU-CVE-2026-54369 | libacl1 2.3.2-2 | no fix yet | acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attac |
| high | UBUNTU-CVE-2026-35368 | rust-coreutils 0.8.0-0ubuntu3 | no fix yet | A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves the user specification via getpwnam() after entering the chroot but before dropping root privileges. On glibc-based systems, this can trigger the Name Service Switch (NSS) to load |
| high | UBUNTU-CVE-2026-35341 | rust-coreutils 0.8.0-0ubuntu3 | no fix yet | A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files. When mkfifo fails to create a FIFO because a file already exists at the target path, it fails to terminate the operation for that path and continues to execute a follow-up set_permis |
| high | UBUNTU-CVE-2026-93658 | rust-coreutils 0.8.0-0ubuntu3 | no fix yet | uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevate |
| high | UBUNTU-CVE-2026-89161 | libpcre2-8-0 10.46-1build1 | no fix yet | In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur. |
| high | UBUNTU-CVE-2026-35352 | rust-coreutils 0.8.0-0ubuntu3 | no fix yet | A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility creates a FIFO and then performs a path-based chmod to set permissions. A local attacker with write access to the parent directory can swap the newly created FIFO for a symbolic link |
| high | UBUNTU-CVE-2026-82560 | perl-base 5.40.1-7ubuntu0.3 | no fix yet | Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space re |
| high | UBUNTU-CVE-2026-48959 | perl-base 5.40.1-7ubuntu0.3 | no fix yet | IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration. |
| high | UBUNTU-CVE-2026-9538 | perl-base 5.40.1-7ubuntu0.3 | no fix yet | Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on t |
| high | UBUNTU-CVE-2026-48962 | perl-base 5.40.1-7ubuntu0.3 | no fix yet | IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through e |
| high | UBUNTU-CVE-2026-42497 | perl-base 5.40.1-7ubuntu0.3 | no fix yet | Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's i |
| high | UBUNTU-CVE-2026-48961 | perl-base 5.40.1-7ubuntu0.3 | no fix yet | IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID. When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causi |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| 17.0.20.1_1-jdk-fixed | Not FIPS-ready | C 354 | 2026-10-01 | ReportFix |